Cask StudioSecurity

Report a vulnerability

Found a security problem in Cask Studio? Tell us first, and we will work with you to fix it.

Email [email protected]. Write in English or Dutch. This policy is also listed in our security.txt.

In scope

  • cask.studio and its subdomains, including the API at edge.cask.studio.
  • The Cask Film and Cask Flow apps for macOS.
  • Cask MCP, the server the apps run so agents can drive them.

Out of scope

  • Denial of service, load testing and spam.
  • Social engineering, phishing and physical attacks on our people or offices.
  • Services we use but do not run, such as payment and AI model providers. Report those to the provider.
  • Scanner output, missing headers or version banners with no working attack behind them.

What to send

  • What the problem is and what an attacker could do with it.
  • The URL, app version or component where it is.
  • Steps to reproduce it, and a proof of concept if you have one.
  • How we can reach you, and whether you want credit.

Safe harbour

If you act in good faith and follow this policy, we will not take legal action against you and will not report you to the police for your research. That means you:

  • Access only the data you need to show the problem, and no one else's account beyond that.
  • Do not change or delete data, and do not keep it once the report is done.
  • Do not disrupt the service or degrade it for other people.
  • Do not use the problem for anything beyond showing that it exists.
  • Keep it confidential until it is fixed, or until we agree on a date to publish.

If a third party takes action against you for research that followed this policy, we will make it known that you acted with our authorisation.

How fast we respond

  • We confirm your report within 3 working days.
  • We tell you our assessment within 10 working days.
  • We aim to fix critical and high issues within 30 days, and others within 90 days.
  • We keep you updated until it is fixed, and credit you if you want.

We do not run a paid bug bounty. We may thank you for a serious finding, at our discretion.